Skip to content

build(deps): bump oauthlib from 3.1.0 to 4.0.0 - #345

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/oauthlib-4.0.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/oauthlib-4.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps oauthlib from 3.1.0 to 4.0.0.

Release notes

Sourced from oauthlib's releases.

4.0.0

Introduction

The release 4.0.0 defines the foundation that enables AI contributions and will improve the maintenance of oauthlib by using AI agents, skills, code for both contributors and maintainers. It includes devcontainer, skills and cleanup of instructions.

What's Changed

Important: this release contains 2 breaking changes. See CHANGELOG.rst for details:

  • Removed JSONP support from token revocation endpoint (#951)
  • Client authentication validation reorganized across grants (#919, #920): the grant_type parameter is now validated before client authentication.

New Contributors

Full Changelog: oauthlib/oauthlib@v3.3.1...v4.0.0

3.3.1

What's Changed

Full Changelog: oauthlib/oauthlib@v3.3.0...v3.3.1

... (truncated)

Changelog

Sourced from oauthlib's changelog.

4.0.0 (2026-09-28):

OAuth2.0 Provider:

  • Breaking: #951: Removed JSONP support from token revocation endpoint. JSONP has been superseded by CORS for cross-origin requests. The enable_jsonp parameter has been removed from RevocationEndpoint and the callback parameter has been removed from prepare_token_revocation_request.
  • Breaking: #919, #920: Fixed DeviceCodeGrant.validate_token_request trying to authenticate public clients. Client authentication validation has been reorganized and is now shared across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter is validated before client authentication, so requests missing grant_type now return 400 invalid_request instead of 401 invalid_client.
  • #963: Improved PKCE code comparison

Misc:

  • #904: Stop installing examples into site-packages.
  • #930: Add devcontainer, Add Python3.14, Python3.14t.
  • #931: Fix ruff checks about unused variables.
  • #932: Dropped EOL Python 3.8 from CI.
  • #934: Pre-commit hooks autoupdate.
  • #938: Fix typos discovered by typos.
  • Add OAuthLib Maintainer agent for automated issue/PR triage and release management.

3.3.1 (2025-06-19):

OAuth2.0 Client:

  • #906: fix regression of expires_in parsing when float in string.

3.3.0 (2025-06-17):

OAuth2.0 Provider:

  • OIDC: #879 Changed in how ui_locales is parsed
  • RFC8628: Added OAuth2.0 Device Authorization Grant support
  • PKCE: #876, #893 Fixed create_code_verifier length
  • OIDC: Pre-configured OIDC server to use Refresh Token by default

OAuth2.0 Common:

  • OAuth2Error: Allow 0 to be a valid state

OAuth2.0 Client:

  • #745: expires_at is forced to be an int
  • #899: expires_at clarification

General:

... (truncated)

Commits
  • 145a9a4 Release 4.0.0: clarify changelog breaking changes and reformat entries
  • c8344d6 Update CHANGELOG.rst
  • e172830 Release 4.0.0: bump version to 4.0.0 and update changelog
  • 40b0ab5 Merge pull request #963 from oauthlib/ft/pkcecode
  • 1b68cea Merge pull request #920 from hekhuisk/validate-client-authentication
  • c951a1d Organized validate_client functions for all grant to avoid mistake in grnat i...
  • 74664d3 Improve PKCE code comparison
  • 9859b05 Merge pull request #950 from oauthlib/feature/3.4.0-maintainer-agent
  • 9bf9b97 Merge branch 'master' into feature/3.4.0-maintainer-agent
  • 1ba7429 Clarify agent instructions
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [oauthlib](https://github.com/oauthlib/oauthlib) from 3.1.0 to 4.0.0.
- [Release notes](https://github.com/oauthlib/oauthlib/releases)
- [Changelog](https://github.com/oauthlib/oauthlib/blob/master/CHANGELOG.rst)
- [Commits](oauthlib/oauthlib@v3.1.0...v4.0.0)

---
updated-dependencies:
- dependency-name: oauthlib
  dependency-version: 4.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Central YAML (base), Organization UI (inherited), Workspace UI (inherited)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: fcc5573c-2110-4569-bb0f-34a88323217c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants